I tried creating a web browser, and Google blocked me
blog.samuelmaddock.com
blog.samuelmaddock.com
"Circumventing" is much more broadly defined than it should be.
It's not just illegal to redistribute copyrighted material. That's the point of copyright and has been the case for a long time. It's also illegal to watch/consume content yourself in any way that the copyright-holder didn't explicitly enable, even if you have a general right to watch/consume that content. You're not allowed to create a browser that can watch DRM-protected Netflix content. And if someone does create such a browser, it's illegal for you to use it, even if you pay for a Netflix subscription.
That's pretty new (circa 1996 or so).
In 2002 I went to see Lawrence Lessig argue the Supreme Court challenge of the Digital Millennium Copyright Act, which introduced these anti-circumvention concepts. Here are my notes: https://allafrica.com/staff/kwindla/eldred.txt
However, based on that premise they've instituted rules to "protect" intellectual property, but unfortunately they're so weighted toward the "owner" of the IP that they do (IMHO serious) harm to regular users and consumers. It seems to me that regardless of which political side you fall under, we should agree that governments exist to protect the rights and interests of everyone, not just a select few.
Something is really wrong here, and getting mad at Google or Widevine or some other company is a red herring. The real problem is what we've allowed our government(s) to do. We need to fight back there. Once the government isn't propping up the companies anymore, their abuse will disappear.
To the established owners of IP. If you're not an established creator, you're going to be on the side that gets hurt by the IP. Some IP claims are gonna hit you sooner or later, and even if they're complete bullshit, you won't be able to do anything about them.
Established owners can generate enough of a fuss that they could cause an outrage big enough for some actual human to look into your issues, but if you're not big enough for that... tough luck. Try again from scratch once Google cuts you out. This happens regularly across their products, be it Google Play, YouTube, or Chrome's extensions store.
It is also legal to do a reverse engineering of software to allow it to run on your system, software, hardware (so I think a browser also applies).
(I'm not a lawyer, just reading some of the more technical law articles)
There are lots of differences in the details, but I wouldn't make a blanket statement that it's completely legal without actually checking the corresponding laws.
[0] https://en.wikipedia.org/wiki/Copyright_Directive#Technologi...
Be careful with that one. The Netherlands had that too until some European court decided that our laws were foolish and went "that's all wrong, it's obviously illegal" after which there was case law about it being illegal and now it's illegal. The ministry immediately went "oh, well, we s'ppose it's illegal then from roundabout last week!"
In case you were wondering who's behind this expensive lawsuit that lasted from 2008 to 2014: we had "home copy tax" (thuiskopieheffing), so you pay a few bucks extra for storage devices (hard drives, usb sticks, smartphones) and that was redistributed to rights holders as compensation for "home copies" (copies for personal use in your household, backups, that sort of thing). Shops did not like that they had to pay extra taxes that they did not have to pay in other countries, so they went to court and got us where we are now.
Dutch news about it: https://tweakers.net/nieuws/95332/nederland-mag-illegaal-dow...
> Nederland stelt dat het downloaden van dergelijk materiaal hetzelfde is als het kopiëren van een cd of dvd, maar daar gaat het Europese Hof niet in mee. Volgens het Hof kan een wet die 'geen enkel onderscheid maakt tussen kopieën uit geoorloofde bronnen en kopieën uit vervalste bronnen' niet worden gedoogd, omdat dergelijke wetgeving auteursrechtinbreuk kan bevorderen.
Translated:
~ The Netherlands claims that downloading of such material is the same as copying a cd or dvd, but the EU court does not agree. According to the EU court, a law that makes 'no distinction can be made between copied from allowed sources and from forged sources' can be allowed, because such laws promote copyright infringement.
Dutch news about the government's response: https://tweakers.net/nieuws/95335/kabinet-nederland-heeft-pe...
> Het is in Nederland per direct verboden om auteursrechtelijk beschermd materiaal te downloaden uit illegale bron, bijvoorbeeld via torrentsites en nieuwsgroepen. Dat stelt het kabinet in een reactie op een uitspraak van het EU-hof.
Translated
~ It is in the Netherlands henceforth prohibited to download copyrighted material from an illegal source, for example through torrent sites and newsgroups. This is the ministry's response to the ruling of the EU court.
So we didn't need any law change, parliamentary debate, nothing. It was in effect right away.
As per https://en.wikisource.org/wiki/Polish_Copyright_Law
Article 23, paragraph 1:
> It shall be permitted to use free of charge the work, which has been already disseminated for purposes of private use without the permission of the author.
Article 6, point 3:
> the disseminated work shall mean a work which, with a permission of its author, has been made available to the public by any means whatsoever
So, it is legal to access the work without permission, if author gave prior permission to make it available to the public. However I'm not sure if selling a book in a store or showing a movie in a cinema would automatically mean that such work can be downloaded freely from the Internet - technically the work is available to the public, but I'm sure the author did not give permission for the work to be available on the Internet.
I'd advise not giving out bad advice then stating absolutes about the legal situation that are wrong.
Try not to help them by paying for entertainment.
That does depend on the countries, at least on my case in France there's an accessibility exception which makes it okay in his case to break the DRM legally because he does not have any other choice.
What if you design a web browser that just ignores most blobs of CSS/Javascript and renders content in a very different way. Are you now breaking copyright? Because you're rendering the data differently than the W3C standard or blocking certain elements?
I realize this is specifically about DRM content, but I feel like it won't be a stretch to try to apply these laws to common content.
Lets all start running Gopher servers again... Fuck the modern web.
that describes every command line / terminal web browser.
HTML DRM is antithetical to the Open Web itself. It was built on a sham of "plugin-free" media playback, but all we did was change Flash and Silverlight for a whole range of closed black boxes, which in turn are effectively all controlled by Big Media (to make it crystal clear: EME was built with third-party decryption modules in mind, and Big Media was obviously never going to support any sort of decryption modules that they couldn't control, so even if your custom browser supports EME it's completely useless without a Big Media-approved decryption module). And make no mistake: Requiring permission from Big Media to essentially build a fully-fledged browser is a 100% intended and expected outcome of HTML DRM as conceived. Big Media would love nothing more than to turn the entirety of the Open Web into Closed Web that they control, and with HTML DRM they've certainly achieved a great step toward doing so, to the detriment of public at wide. I'm sure they're positively salivating about the thought of eventually reaching The Right to Read![2]
It's _always_ been about control on the creation and manufacture of playback platforms and/or devices.
content is no longer the only draw. the business goal is now monetizing the group experience. consider Fortnite. Companies won't care if a few people watch pirated content alone. They want to control the experience of group content consumption. This does require content, but managing the group experience is the new frontier. consider http://rabb.it Pirates can get ppl in groups to watch premium content, but at some size, authorities will show up to protect their property.
What counts is whether adding DRM increases revenues enough to warrant the effort needed to add DRM.
there's no getting around it. if you want it you have to play by their rules.
Much less guff to download.
As interesting to read as the first twelve times.
https://www.wired.co.uk/article/cory-doctorow-walkaway-scien...
He used(still does?) publish his books free of DRM and free to download under CC license.
https://craphound.com/overclocked/download/
It would be strange for an author of Printcrime (fantastic short read from 20 years ago) to support DRM.
This requires the use of the widevine library which then downloads things behind the scenes upon use (I believe). https://forum.kodi.tv/showthread.php?tid=329767
I can't imagine Google gave the OK to Kodi to use widevine so maybe you can see what they did?
Edit: Forgot link https://aur.archlinux.org/packages/chromium-widevine/
And... they are using chromium. Can I be sympathetic to Google because they have to pay people money to support this?
> The docs on how to do simple things seem to be nonexistant because they don't want to be sued and shutdown entirely.
What docs are you looking for? They have a very extensive wiki as well as an active community on their own forum.
Kodi uses the OS native implementation of the DRM, or Chromium with Widevine.
- When I want to watch movies on Amazon Prime Video, there are some movies I can't watch in HD, even if I paid for HD (so the movie obviously exists in HD; probably dependent on the rights holder). The problem is that I can't see if I can watch the HD version before I buy the movie.
- On Netflix, I don't get 1080 at all with my browser, even if I pay for 4k.
- Every few weeks, Spotify pushes a broken version of their web player to the website and from one moment to the other, I can't listen to 'my' music anymore until they fix it. The good news is that it seems to happen less frequently lately. Nevertheless, that would not be a problem if I could listen to 'my' music with a normal mp3 player.
- A few hours ago, I wanted to play a game, but guess what... Steam had a network problem [1] and didn't even let me enter the offline mode.
I think Steam is a really good (not shitty) DRM enforcer. A very occasional lapse in service is acceptable for entertainment platforms. I use steam because it is actually easier to use their DRM systems than it is to, for example, buy CDs or download individual game installers.
I would generally agree that this is acceptable, but it's still a step backwards from Itch and GOG, where my library literally never has a lapse in service. Steam is arguably one of the best DRM solutions out there, but even the best solution on the market still has worse uptime and reliability than a store that just provides users with a bunch of DRM free downloads that they can launch offline whenever they want.
Of course, platforms like Itch don't have cloud saves. But Steam's DRM isn't essential for cloud saves, or for the community workshop, or for the storefront, or for the library management tools. The DRM part of it doesn't add any value to the consumer. So while Steam is an excellent product, Steam without DRM would still be a better product than it is right now.
That's what people mean when they complain about DRM. You can take a great product and add DRM in a way that doesn't completely break it, but it's still pretty much always a strict downgrade in user experience. People look at services like Steam and think, "yeah, this is acceptable. But it could so easily be really great."
It may be a good DRM enforcer, but as a UI it's terrible and intrusive. There's no way to turn off all those popup messages and game related alerts.
I had to give up on steam once they started doing that.
[1]: https://medium.com/netflix-techblog/per-title-encode-optimiz...
And if you have the right combination of browser, os, Intel CPU, GPU and monitor to have intact DRM of the required level, Netflix will stream you the 1080p or 4k stream
Consumers are not going to put up with all sorts of shenanigans regarding browsers, monitor support etc. etc. - it's an ugly mess.
If it 'just works' - then I think most people will accept 'paying for content' as a premise.
But when the pieces don't fit together because industry players don't see the 'big picture' ... it will just be bad for everyone and ironically encourage piracy.
Bluntly I expect Netflix could stop supporting PCs and browsers entirely and feel very few negative effects.
That is what DRM is about preventing.
If some knowledgeable people can copy it and put it low-fi on some competitor of Youtube and Google doesn't show in in search results. That isn't that bad. That means the general public won't easily find it.
The link mentions that to produce a HDCP-compatible device (eg one that has an HDMI port) it needs to be licensed, pay an annual fee, and make promises to frustrate DRM-mitigation efforts.
If I wanted to make my own monitor with a VGA input (or, more practically, pipe the signals coming from VGA into a program that does something with the feed) I would just have to find a suitable adapter and receive the serial data.
Does this mean that doing so with HDMI (either the real-world DIY monitor, or the in-software feed-ingestion program) would be:
A) Difficult/time-consuming to write due to a lack of open drivers B) Run afoul of IP laws pertaining to the HDMI standard and get me sued C) Prevented by the cryptographic handshake that happens between an approved display and the output drivers D) All of the above?
For HDMI, specifically:
A is true, as HDMI requires a pretty ugly IP core on an fpga or an asic to process or produce the phy.
B is also true, as to sell a device with an HDMI port you have to join the group and pay fees. If you're just hacking stuff together for personal use I think you're A-okay here.
C is true ONLY in the case of HDCP protected content, as that handshake does not occur for unprotected content or HDMI 1.0
Also, side note, VGA uses analog R/G/B channels so if you want to pipe signals into the program you'd need an ADC to get useful values from it, and a pretty fast one depending on your resolution.
Inputting any pulse-based high-frequency signal is more difficult, be it VGA or Ethernet or HDMI.
Also, old keys are frequently phased out, with new media requiring newer keys for playback.
(I wonder if the same people who are up in arms about China's lax IP laws and massive product counterfeiting realise that it's the same country, the same culture, the same mentality which allows them to easily produce these devices that actually fight for your freedom to consume content.)
If an ISP fully embraced the Net Neutrality repeal and started blocking video content, and someone posted on HN that ISPs were "blocking them from building a streaming service", no one would be complaining that, "technically you can build it, you just can't reach any of your customers." Everyone on HN would understand that part of building a service is the having the ability to reach customers.
In the same way, part of building a web browser is having the ability to render web content. If Google can block your custom browser from rendering content, then for all practical purposes they are blocking your ability to build a browser.
Because those third party sites choose to utilise closed software from that company. And Netflix doesn't only utilise Widevine as a DRM, it uses several different DRM systems, so Google don't have control over anything.
That's just a sensationalistic as the headline. There isn't a single company controlling and selling these modules. There is a several of them, in open competition. The OP chose Widevine because they are easiest, but with sufficient perseverance he could probably use any of them, or at least any that distribute x86 binaries. It's damned near impossible to prevent someone from running a binary if they really want to.
I also found the original article difficult to swallow. It gave very little detail - so little we have no idea what Widevine said no to. For example, was it "could you provide Widevine and loan me an engineer to help me integrate it with my browser - but I can't pay you because it's all open source". Or was it "I've got it all going, I'm willing to pay you commercial rates per licence - how can I buy licences?" It if is the former hats off to Widevine for replying at all.
As it is, we only get a small part of his side of the story, no insight at all into why Widevine reacted they way they did, and a headline that's guaranteed to get clicks.
Call me paranoid, but I get the feeling I'm being manipulated.
Eh.. in a way, but not really. It can still work as a web browser but a web site can still render however they'd like based on your user agent.
If I made a site today, I could add the same functionality if I wanted to. Since I own the site, that's my choice.
I completely agree that Google should _not_ block their content based on your custom web browser. That is evil.
I completely agree that this is unacceptable... but I think the blame really rests on the content owners who forced this DRM in the first place. Every damn thing on Netflix is widely available on torrents in hours, so it's totally useless and just makes things worse for everyday consumers.
OP sounds like he feels entitled to others' work and efforts. If he wants to play videos in his browser, he can make them. Or find people who will make videos for free for him.
All OPs browser does is syncronse playback across users legitimate Netflix (or other) accounts.
OPs broswer will pass the encrypted video through to the DRM plug-in, which will authenticate from Netflix through to the to the screen. It will decrypt the video, decode it, re-encrypt with hdcp and send it to the monitor.
The DRM chain is intact. OPs browser can't be used to pirate the videos, or steal Netflix.
All he needs is permission to ship the closed source DRM plug-in.
Widevine is only one of several implementations of a Content Decryption Module; it just so happens to be by far the easiest to license (though that doesn't mean that's easy!).
I would think that Amazon would lead the charge for an open standard for distributing video which handles DRM, subscription, pay per view, etc. and then all the non-Netflixes would publish to that standard, and let player applications thrive. Even when using a Roku it feels like each app is completely different. And most of them suck. Imagine if in 1985 Prism, HBO, and Showtime all manufactured their own TVs and required you to use them, but they all had wildly different layouts and remotes.
The idea of syncing up two video streams is awesome, I can see people enjoying that, and it would encourage people to pay for whatever services their friends have. Though it does sound a bit similar to rabb.it
I would prefer to have NO DRM of course don't get me wrong. But still in this case, it is not your decision and apparently most people really don't care for that at all. They wanna see netflix in there browser. Thats why google and co did it. Thats why no one cares that there might be a electorn based browser somewhere which is unable to implement its core feature of sync viewing.
And while i like the idea, just because is just not good enough. Noone will cancel there netflix subscription over this.
I would want someone to correct me on a fundamental grammar mistake in Spanish, so I felt it would be useful to correct you here.
Firefox compatibility is valuable because Firefox extensions don't have to be distributed through the Mozilla add-on store (they do need to be signed by AMO, but provided your extension isn't doing anything illegal, that should not be an issue).
Finally, you could try redistributing unbranded Firefox or Chromium with your extension pre-installed. Waterfox (a Firefox fork) can have DRM — it's disabled by default, but it can be switched on — and I don't think they put a great deal of effort into it, so I think that your "version" of Firefox could also easily have DRM. (I have no idea whether the same holds for Chromium.)
I would much rather have a webapp than have to download a whole new browser just to watch videos with a friend. Most of the stuff listed on the github (WebRTC, WebSocket) are just normal web technologies. The only other thing I see is "Discord Rich Presence".
One of the main requirements I wanted was the ability to use the app with as little centralized dependencies as possible. P2P is the primary way to connect to users with the app, but even that requires a centralized signaling solution which is prone to downtime. To mitigate this, users can also directly connect to an IP address with the appropriate ports forwarded. Listening on a socket is not supported by a web extension at this time.
Additionally, some actions on the web require a "user gesture" to be performed such as fullscreening a video. I created an auto-fullscreen feature by simulating a user gestured mouse click. It also only fullscreens within the frame of the window instead of the entire screen. [1]
Other features not possible with a web extension/app include local file reading (potential future feature) and Discord Rich Presence (currently implemented).
That makes sense and it's interesting to see the limitations of the "web extension" framework.
The following isn't meant to try to convince you to use any particular solution (I don't have any skin in the game), just some ideas in case you get fed up even more by the problems with implementing DRM in your own browser.
Listening to a socket and reading local files is possible with "Native messaging"[1]. In brief you have a small application running in the background, outside the browser, which can listen to sockets or read local files, and your browser extension communicates with it. This does bring added complexity and might (haven't tested) bring additional latency, possibly making it unacceptable.
[1] https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
If they had held fast, we could have forced the companies to do their key management in something like WebAssembly and avoided this gatekeeping mess.
We have DRM, we hate it but it's there, and it serves a purpose. If it is your intellectual property, you get to decide how it is used. And if you don't want to make copying too easy because you think that it will get you more money, that's your right.
The goal of the W3C is not to make to make a political statement about the rightness or wrongness of DRM. They are here to create standards that respond to use cases. And unfortunately, copyrighted content diffusion is one use case, and content owners want DRM.
And if you read the standard they came up with, it is not that bad. They managed to isolate the "evil DRM" part well enough without completely destroying its effectiveness. They also didn't require any proprietary component, though services can require them (that's what happened in the article).
Using WebAssembly (which is essentially optimized JS) for DRM is a terrible idea IMHO. DRM, to be effective, usually requires access to protected system components. It means that to make an effective enough DRM to be accepted by content providers (which is the entire point of the standard), we would need to give WebAssembly way to much power.
>And if you don't want to make copying too easy because you think that it will get you more money, that's your right.
They seem to think that but is there any truth to it? I do pirate some series/movies from time to time (mostly out of convenience) and you can get high quality rips of pretty much anything mere hours after it's available on streaming sites anyway.
So what is this DRM supposed to achieve? Prevent the average non-technical user from saving the stream? I mean I'm sure they wouldn't even know where to start, there's no "Save As" button on Netflix for instance. Simple client-side limitations would do the trick for 99.9% of the population. On the other hand the few technically-savvy stream rippers seem to have no issue bypassing these protections.
DRM works better for interactive content like games because it's not just about ripping the output.
How many decades do we have to suffer through this broken scheme and this technical debt until the right owners realize that they're wasting their time and their resources to push a system that only serves to make it harder for legit clients to consume their contents?
When iTunes got rid of DRM on music files I thought it would be the tipping point where right owners would realize that this scheme was ineffective and counter-productive, but apparently it's still an industry standard for some reason. Have legit users on unsupported systems stream low-res video while the pirates can watch it in 4k for free. Ridiculous.
Another poster here made an interesting point, that this wasn't true until the 90s. Deciding "how it is used" is different from (and broader than) deciding "who gets to distribute it".
But of course they didn't say that, because most of them got some direct or indirect interest in DRM, enough so that the few remaining players did have no choice than to hop on board, too.
Having worked with various DRM teams I know that they have to treat their code as if its the most secret code in the world, if they don't the media companies can swoop in and ban them and then no Netflix for your users. This is why Widevine code isn't open source (other than the glue EME code) and is almost certainly the reason for the refusal to work with a small open-source form of Chromium. If for example the project was used to "steal" content the media companies would be mad at Widevine, with lasting repercussions for all Chrome users.
It's worth noting that typically all DRM teams work as if the hosting environment is an adversary. For example Widevine don't trust anything Chrome says as someone could recompile it and lie about the security. The only times this is relaxed is where the platform is deemed secure, such as CrOS or iOS.
Does Netflix DRM even "work"? I've never personally seriously looked around for how to break it, but I note there are still plenty of people who seem to manage to review Netflix-based shows on YouTube with video clips of sufficient quality [1], and at least some of the reviewers in question I am fairly confident aren't getting any sort of privileged backdoor access or anything.
Is it "anyone can crack with a smidge of effort" or "it's really hard but it spreads once cracked"? I'm not asking for a lot of details of the crack per se, just general details of how successful it can be said to be in practice.
[1] I'm not claiming they aren't necessarily re-re-encoded by the time they get to me, but if they are, I can't tell for sure, so I'm going with "sufficient quality" as a description.
And they did it for the worst reasons. Vanity and pride. The corporations pushing DRM are merely motivated by greed.
But the players in the OSS community that opened the door for DRM were TERRIFIED of being labeled as "obsolete" or losing pretend "market share". They refused to take a stand against DRM, if it meant losing any users. Just look at the discussion thread where Mozilla decided to support DRM.
The arguments in favor of DRM by the OSS community are always the same: - We need to support terrible DRM because it is popular (and being numerically popular is super important). - We need to compromise against our users because if we don't then we won't have any leverage (which we are conceding we don't have anyway) - "marketshare" - "integrated branding"(?)
None of this makes sense, because Google, Apple, and Microsoft have completely different goals with building for-profit forms.
People who speak in slimey business sales marketing speak are making decisions about the direction of OSS software. And these people are obsessed with cargo-culting the big commercial platforms.
My guess is that, if browser vendors wouldn’t have played ball, the DRM vendors would have worked with one of the JRE vendors to optimize the Java applet runtime, and contributed to performance improvements on the browser side for all the open browsers, such that “Java applet” would no longer be a scary heavy-weight thing nobody wants their browser to launch. That would be (one of) the implicit threats hanging over browser vendors: if you don’t cooperate, we’ll take your control over innovation on the web away by refocusing it on an improved Java experience.
And if the browser vendors really didn't like it for unknown reasons then they could have just stopped supporting Java in the browser, as has largely already happened for various other reasons.
This is one of those "we all must hang together or we shall all hang separately" situations, and they apparently decided they'd prefer to hang separately.
It's sub-optimal, but I don't think an optimal solution actually existed. A standards board divorced from reality is no better than no standard at all.
That's fine. It's better that the burden for maintaining non-standard plugins be put on the sites and browsers that choose to do that, rather than be placed on everyone else.
The majority of the membership was in favour, definitely, but it wasn't unanimous. Some members I think it's predictable how they voted (MPAA may have voted in favour, EFF may have voted against); others less so.
Without W3C DRM they would have kept those plugins alive instead of deprecating them. I see no reason why they'd have migrated to webasm, webasm wouldn't provide the know-thy-customer aspect the DRM people want.
It really isn't. The W3C at the very least permits a solution whereby content companies liberally distribute binary blobs for every platform under the sun. Hell, it even permits an open source solution that e.g. speaks directly to the DRM hardware in graphics chips (don't know if that would be technically feasible, don't shoot me).
It doesn't have to be this way.
In this context it's really specifically Google being assholes about this. They can choose to not be assholes about this. The fact that the W3C allows them to be assholes about this doesn't change the fact that Google is choosing to be this way about it.
It's been more than a year that I'm in contact with Google/Widevine, waiting for my license.
This is a nightmare. It's such an obvious gatekeeping mechanism.
Bonus DRM: If your license is not "the most certified" your browser/player will play only shitty/low quality versions of the video. There are other goodies of course like not being able to play the content offline.
>As far as I’m aware, Widevine is the only available DRM for a Chromium-based browser, especially so for Electron.
It can too be completed, you're just not gonna have DRM'd content. I have a browser that has the same problem, and I just leave pages that can't do video playback (which doesn't include YouTube because they use WebM). There's still value in a non-DRM'd browser for most of the web, and hey, if enough of us use one maybe sites will start being more liberal in the licensing of their video (but let's be honest, probably not).
This assumption is a mistake the author is making. Chrome is, for all practical purposes, closed-source and proprietary. It's Chromium that is open-source. So far as I know, Chromium does not have Widevine included by default.
It may have been a stupid decision for W£C to include DRM in the spec, but frankly the rest of the internet doesn't give a shit - As far as OSS is concerned it's another 3rd party blob like flash and not a true part of the web. As far as I can tell the author is trying to use this third party blob specifically - not the rest of the browser for which no one has any authority in the creation of...
So, switched to Firefox. Firefox then also had it break on Debian/Gentoo: https://bugzilla.mozilla.org/show_bug.cgi?id=1475260.
Chromium, and other FOSS browsers including Firefox, do support Widevine. It is a giant proprietary binary blob, yes, but there's support for it. (And yes, I wish everyone would adopt and obey the tenants of free software, but alas.)
Chrome is not an open-source browser. Chromium is, and Chromium doesn't have Widevine support.
Download and sandbox the Widevine binary blob the same way that Firefox does. Done.
Mozilla has a license to redistribute the binary. You can't simply do that (legally).
We don't know anything about the conversation with Widevine other than that they wrote, "I'm sorry but we're not supporting an open source solution like this". They clearly are supporting an open source solution like Firefox. So what is the difference, and can Metastream be less "like this" and more like Firefox?
From a balancing test standpoint, if you want a technological solution to people copying your work then I think you should not be allowed to claim copyright protection of your work. Pick a legal or technical solution to unauthorized copying, not both.
That said, the media industry as a whole has pushed more than what's necessary to protect its content (eg. DMCA, extending the copyright window) and a more fruitful course of action is to get Congress to change those laws.
A WebExtension could work, but has potential to run into the same gatekeeping issue of being removed by Google from their Web Store. With Google having ~70% market share, this wouldn't be a good outcome.
Another option could be creating two extensions: one for the video syncing, and one for the non-window-resize-fullscreen. That way if the latter gets rejected it wouldn't affect the former.
Note I'm sure some people definitely prefer the desktop app approach and I wish you all the best getting the approvals you need for that. This is just how I would prefer to use it.
> such a large percentage of the market is unacceptable.
Umm... expecting any kind of response from a vendor with such a large percentage of the market is... kinda arrogant.
Who are you to demand any kind of response from anyone? Big project or small? You'd probably be less offended if you had a better sense of self awareness about the nature of your relationship with Google.
Thinking that Google should kowtow to your desire to build a product is pretty foolish. You need to build a product and get some traction and then have some leverage. Widevine is evil. Google is evil.
... but so is Electron, and requiring your users to use a custom browser to use your product / feature. How about an Web Extension that coordinates playback in the browser, as opposed to a whole custom browser?
This line of thought is exactly how companies take over open markets and kill them. Google proposes:
A) "It's fine for DRM to be standardized, because anyone can just ask us to use implementations like Widevine."
then follows up with
B) "We can't possibly be expected to handle every single request that we're given! Give us a break, this is hard."
If Google wants to be the web's gatekeeper for who's allowed to stream video, then yes, they'd better be really stinking attentive to little hobby projects and startups. Because they chose to take on that responsibility.
If they don't want that responsibility, then all they have to do is stop gatekeeping. Distribute Widevine as a binary blob, but come up with some universal terms so that any browser can download and distribute it without asking permission.
I don't have much more context in this person's project than anyone else, but your response is kind of the point, one vendor has too much power because they can't be expected to support any kind of innovative ecosystem; yeah, that's not a great state of affairs, and begins to echo/suggest anti-competitive practices (whether on purpose, or just as a function of their size)
I had a couple side loaded extensions, and the nag got me to do what google wanted, stop using them altogether.
1. Why do you have to be so rude? Maybe this isn’t intentional, but your words are mocking and insulting. Do you actually think you could change someone’s mind spouting off like that? If so, you don’t understand humans. If not, that comment was a giant waste of time.
2. If the way you spoke to this person represents how you wish to conduct yourself, perhaps it would be wise to remove the ‘we’re hiring’ on your profile. I’m not looking, but if I was, I would avoid your company based on this comment.
How is expecting a response in less than 4 months arrogant? If anything, the OP has been extremely patient.
> Thinking that Google should kowtow to your desire to build a product is pretty foolish.
Is open and fair competition in the marketplace also foolish? Regardless of what current regulations are, I wouldn't describe open DRM as "kowtowing" to a competitor -- if we value open and fair marketplace competition, then DRM ought to be open.
> Who are you to demand any kind of response from anyone? Big project or small? You'd probably be less offended if you had a better sense of self awareness about the nature of your relationship with Google.
Your response seems to suggest that the OP should happily grovel at the feet of Google and be ever so thankful if Google manages to find the time to make a reply.
If Google wants to be a gatekeeper for DRM, then that's not how things should work.
Are you saying Google is too big to be responsible?
Amazon is huge, and I'm able to get a customer service represenatitve in seconds.
This really isn't a customer support question.
> Umm... expecting any kind of response from a vendor with such a large percentage of the market is... kinda arrogant.
Are you suggesting we all bow obsequiously to the great corporation?
Widevine does not come bundled with Firefox & Chrome. Each installation has to download the Widevine binary. You would be able to use the binary to implement DRM support, like Kodi did.
"Don't be evil" has been changed, remember? They now embrace evil, they love it.
Edit: downvote this all you want, I really don't care. You're going to be at fault for the destruction of the web in the future.
Stallman strikes again
Also, thanks for pushing on them. I've seen numbers posts on HN recently about the opaque walls folks encounter on Google, Amazon and Facebook property monopolies. This is just another great example. Would it make sense to file this with the EFF? Someone has to be collecting all of these issues for the impending class-action suit?
1. Firefox consumes the Widevine as a plugin, and the way to load that may be a straightforward one, through an interface.
2. Support a different DRM scheme that has an open interface and is popular
3. Disassemble Widevine or talk to hackers who've understood it. Clean room disassembly is legal in many parts of the world.
4. Don't drop this project, but put up a placeholder and evangelise better DRM standards. Pretty sure that if it involves crypto and it's not open source, it is an attractive target with an exploit in the works. That's what it is going to lead to, and by then you'd already have a working implementation.
"Metastream: Watch streaming media with friends."
He's complaining that they won't let him use DRM. But his project's purpose is to literally broadcast media to your friends.
DRM exists to prevent that.
Judging from the repo, there is no broadcast of content. Please take the time to read and think critically before you react with misinformation
The best implemented DRM makes it hardly any more inconvenient for people to use it, and people accept it most of the time, Steam for example. It always puts some people off, who end up pirating it when they wouldn't otherwise have, though.
Even the best DRM is always cracked by those that want to. There is no DRM system that has ever been created that will not be defeated, because it is trying to achieve the impossible. You have to give legal consumers access to the content to consume it, so they always have access to copy it. It will never work. If DRM didn't exist, piracy would be a lot less common.
Most people stopped pirating music when it became easily available without DRM.
Ultimately, all DRM gets cracked, and this is the only real response to it.
Annoyingly, DRM only doesn't hit sales harder because it is defeated. If it was impossible to defeat a particular piece of DRM, it would harm sales of content using it much more, but the harm to the content sellers is limited by the fact that it is always cracked early on and made available to consumers they have cut off. For example, I have a Netflix subscription, which I use in an otherwise open source browser, using the widevine plugin ripped out of Chrome. If this wasn't relatively easy, I would just not use Netflix. Netflix is only getting money from me because the DRM they use is easy to defeat illegally. If the DRM worked, I'd stop paying for Netflix, because I wouldn't be able to use it and it'd be much easier to watch the same content by downloading it from Usenet.
I write a few posts about it here:
https://getpolarized.io/2019/02/13/microsoft-blocking-electr...
https://getpolarized.io/2019/02/28/dear-app-stores-dont-bloc...
It took me four weeks to unblock me and I finally had a chance to re-publish to the MS app store and I'm waiting for their final approval of my app.
YES.. I can develop the app without being in an app store , but my distribution will be dramatically reduced.
Doesn't make sense to have an app with no users.
Google is probably not actually targeting this app specifically just that they've been insanely incompetent lately and screwing over developers ALL over the ecosystem including Android, Chrome Extensions, etc.
Our chrome extension continues to need approval every time we publish it EVEN if we just update the assets/images.
Google is really dropping the ball and pissing off developers left and right.
Over at /r/androiddev people are actually talking about protests at Google IO...
https://aur.archlinux.org/cgit/aur.git/tree/?h=chromium-wide...
Basically Arch Linux Downloads Google Chrome, Extracts the *.so file and puts it into the chromium lib directory. (This could've been done in his own browser aswell.
sudo pacman -S chromium-widevine
error: target not found: chromium-widevine
Just to set the record straight, the author's browser is based off Chromium, funded largely by Google. However, for whatever reasons (and I can see many legal ones for the inability to license a DRM module), Google cannot license the DRM module. The author is free to implement it himself, Google is not "blocking" him.
Another point of note - the author is NOT entitled to widevine, so this pitchforking of Google is simply uncalled for. If the author finds Google to be "blocking" him, maybe asking Apple or Mozilla for WideVine support in a browser that competes with their own offerings is a way to go, and to validate which company is actually willing to work with competing open source offerings
How (re)usable is Adobe's Primetime DRM for something like this? Primetime was removed from Firefox in version 52 (pre-Quantum) in early 2017 [1]. Are there any others?
[1]: https://www.ghacks.net/2017/01/10/firefox-52-adobe-primetime...
> For Windows Electron/Chromium will not work with PlayReady at this time. I have provided your feedback to the engineering team for future planning. Currently PlayReady can be integrated in a PWA/(Windows Store HTML/JS app) and there would be no royalties on Windows.
Don't allow DRM sources hulu/netflix otherwise make a deal with each company. Your problem is with the video providers not a third party who has a solution you want to use.
https://support.mozilla.org/en-US/kb/enable-drm
"Firefox for desktop supports the Google Widevine CDM for playing DRM-controlled content. Firefox downloads and enables the Google Widevine CDM by default to give users a smooth experience on sites that require DRM."
Firefox does support either exactly this or something compatible.
Does anyone know if there is another way of going about doing this?
The browser should explain clearly what's wrong and what to do when a site requires DRM. Don't be like QuickTime, where opening any unsupported file bounces you to a FAQ page where the question you most likely have ("how do I view this video") leads to a huge run-around.
Um, duh?
These entities have elected to participate in two communities - open where it commoditizes their competitors (e.g. Chromium, Netflix service infra) and closed where it protects their differentiation (e.g. Chrome, Netflix licensed content).
As an open community, instead of demanding access to the gated communities, and whining when companies innovate behind walls, we should be building better, richer solutions in the open.
The only thing I wonder here is that DRM was a thing when he started working on this project, didn't he see this coming? By this I mean that project research should start with the hardest part, at least that's what I usually do.
As for DRM users, just post a version with the crack somewhere with a tor browser and fake identity and let the streisand effect be.
That doesn’t sound right. It should either say “open source browser Chromium” or “closed source browser Chrome”.
To get around the legal issue that they won't do this for an open source project, just create a shell corporation.
That shell corp then writes a closed-source plugin wrapper in another project entirely.
Put widevine in that wrapper. Then your open source project just has to include that plugin.
I'm trying to bring to light a bug that allows to skip Ads in YouTube (no add-ons, extensions, etc.), but just can't get any attention: https://twitter.com/maketechfair
If yes, what's the difference which allows Chrome to work with DRM and doesn't allow another code to do that?
I don't think I understand the problem. What does it mean "won't allow DRM" - you can always write code which you like, right?
https://wiki.archlinux.org/index.php/chromium#Widevine_Conte...
Chrome browser (which is based on Chromium, plus various Google proprietary features on top of it) is not.
But, I mean, Google is crappy. No surprise there.
Is there some reason you can't make a fork/distro of Firefox?
Uhm... Chrome is positively not open source. Chromium is.
Getting past this technicality, I can't help but wonder what other browser vendors that have forked Chromium did in order to not get blocked.
If so, couldn't you just copy and paste the implementation into your browser from the chrome source?
Chromium is open source, and Chrome may _look_ 99% identical, but we have no idea what hidden differences there are between Chromium and Chrome, because Chrome isn't open source.
* Google didn't can can't block a new web browser from working. * OP is making an _opensource_ browser * OP's browser is specifically made for showing videos in some kind of P2P architecture. * OP is upset because he can't play some other peoples' videos in his new browser.
The R in DRM, standing for Rights is relevant: this isn't your content, OP. Thousands of creatives, artists, and investors put time, sweat and blood into these. They've chosen DRM as the way to get paid. You have no right to their content. If you don't like DRM then vote with your feet - watch others' content, and find another way to compensate them.
Still can't get 4k anywhere.
Because I had this idea and was wondering what tech would be required to solve it.
It's a lose-lose-lose proposition.
For example, if you are browsing the web without looking at pictures, I sometimes find Lynx useful to filter out the clutter.
Microsoft got broken up for anti-trust behavior that is PEANUTS relatively speaking today. Bill Gates was right, (proven overt time) - that the OS is not the competitive advantage - its the platform and ecosystem as a whole.
Google should be broken up, so should facebook and so should Apple.
Amazon? I don't know they seem fairly diversified and although are decimating e-commerce its a more difficult sell.
The web is mostly open, but there are still things out there built to explicitely prevent users from doing what they want, and it seems that even firefox supports this tech.
Thats an assumption i would say is not given. If you build something like this and you expect to support DRM, do your homework on DRM before you start building stuff around it.
You need a DRM "capable" video component to be allowed to play most internet video content that isn't directly user generated, or news.
The consequence is that the giants holding the rights to these components are effectively holding the keys to a decent chunk of the internet. For a browser specifically made for synced playback of movies, they essentially hold the keys to all of it. The big movie studios simply won't allow either streaming or download without you using one of these solutions on both ends of the stream.
The author applied for some form of license of the purportedly free and open Widevine DRM component which is used/approved by almost all big streaming sites. The request was rejected citing a somewhat odd reason: That the project was open source.
This is odd because https://github.com/castlabs/electron-releases is open source, apparently "blessed" by Google/Widevine, and available to use on the only condition you get a license from Widevine. Which should then be impossible?
Which leads us to several somewhat plausible conclusions. Either the author requested the wrong licence/needs a feature not available in previously mentioned projects, someone at Widevine made a mistake, or there is a lot of smoke and mirrors going on to either make it seem Widevine is accessible to anyone when it truly isn't.
Google got the authority from everyone here who accepted chrome and IE DRM by default, to the point that even Firefox was forced to give in, so you all could be sedated by Netflix and other DRMed content.
For basically all the users, this works great; demand for a new browser is low, for streaming media pretty high.
I work in this space and I think the EME path has been a fairly elegant solution for a lot of what was preventing us from being able to use HTML5 video, including DRM but also live streaming and its ilk with HLS/Dash and being able to quickly implement new codecs and transports. Having to fall back to a flash player was never ideal.
If you want to make an argument that DRM is bad, or, maybe more relevant, ineffective I'm not sure I'd argue with you. However I think the solution we have in place has made the video ecosystem in the browser better and did it quickly.
The issue here is about commercial use of a product and while we can blame Google as the owners of Widevine this really doesn't have anything to do with Chrome - outside of the fact that the author was able to quickly create his own browser based on open source components upon which Chrome was based.
Do you really, REALLY think that the very small number of people who are ever AWARE of this issue were enough to make a dent in it? So we could be sedated by Netflix? This attitude is intolerable and more harmful to the community of people who want a free web as using Chrome and watching Netflix is.
However I simply cannot empathize with you because you made another Webkit/chromium-based thing, and that is certainly not the thing we need right now. With Google monopoly in the web the thing we need is the actual good deviation of their w3c 'standards' realization, like Firefox.
Reskinning Chrome with arguably useful "multiplayer" play-pause feature is just meh.
The title is nothing but a textbook example of clickbait: it's sensational but worse, it's deceiving (Google's response is NOT at all related to your electron based browser with <0.001% market share, nor has Google "blocked" you in the first place...)
Gosh I am angry.
So he built an app that is a thin layer over someone else’s app, to play someone else’s content, and he’s upset he cannot get for free the nice things someone else paid for (in development time). My heart bleeds.